> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/july-2025/feature-enhancements.md).

# Feature Enhancements

The Cortex XDR 3.15 release includes the following enhancements:

**General**

| FEATURE                                              | DESCRIPTION                                                                                                                                                                                                    |
| ---------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Linux Kubernetes Platforms                           | Support added for Google Kubernetes Engine (GKE) Autopilot                                                                                                                                                     |
| German healthcare data control with Cortex XDR Cloud | Maintaining control of data privacy and security for the public sector and regulated industries in Europe, Cortex XDR cloud region for Germany supports strict data privacy and service localization controls. |

**API**

| FEATURE                                                        | DESCRIPTION                                                                                                                                                     |
| -------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Create Distributions API now supports Kubernetes installations | The Create Distributions API now supports Kubernetes installations, helping you automate and streamline the deployment of the agent in Kubernetes environments. |

**Detection Rules**

| FEATURE                         | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| New and improved Analytics tags | <p>New analytics suites:</p><ul><li>EDR Windows C2 Analytics: An innovative analytics detection suite that provides visibility into C2 and exfiltration traffic using our novel approach that fuses EDR process context and network-based features. This approach uncovers a broad range of attacks, from overt malicious communications to those involving seemingly benign implants or remote hosts.</li><li>EDR Linux Shell Analytics: A new, advanced Analytics-based generic detection suite that detects abnormal Linux shell executions, surfacing unknown exploits, stealthy backdoors, and post-exploitation activities. It also highlights attacker tools and powerful system commands run in unfamiliar contexts.</li><li>EDR MacOS Shell Analytics: A novel analytics-based detection suite tailored to the macOS domain that detects unusual spawned macOS shells. It uncovers unknown exploits, stealthy backdoors, and the uncommon AppleScript and information-gathering activities commonly leveraged by macOS infostealers.</li></ul><p>Improved analytics tags:</p><ul><li>NDR Lateral Movement Analytics: Upgrade to our network-based lateral movement detection suite, focusing on richer application logging for deeper protocol-based context. The suite's enhanced behavior-based analytics now provide earlier, more precise lateral movement detection, including SSH and improved Windows-native protocols.</li><li>EDR macOS AppleScript Analytics: Expanding our AppleScript attacks coverage by introducing visibility into module events.This enhancement extends our detection of suspicious AppleScript executions to trigger alerts also on executables loading AppleScript dynamic libraries (dylibs) for potential malicious use.</li></ul> |
| Improved Analytics Insights     | View the full list of detections behind the analytics and behavioral indicators of compromise (BIOCs) directly in the Cortex XDR console, so you can instantly understand why alerts were triggered.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |

**Broker VM**

**Version 28.0.96 (reboot required)**

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)

Deprecation of Broker VM Pathfinder applet

The Broker VM Pathfinder applet is now deprecated.

* From this release, the Pathfinder applet can no longer be activated in new tenants or existing tenants that have never implemented this applet before.
* If this applet has been implemented in your tenant, it will remain available until January 25, 2026, which is the official deprecation date. To ensure complete coverage and protection, we recommend deploying XDR Agents on all endpoints by this date.
* Migration guidance and deployment resources for XDR Agents are available [here](https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Documentation/Step-3-Install-Cortex-XDR-agents).
* For questions or transition support, contact your [Customer Support team](https://support.paloaltonetworks.com/Support/Index).

| FEATURE                                                                 | DESCRIPTION                                                                                                                                                                                                                                                                                                                             |
| ----------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Broker VM applet configurations preserved when deactivated              | Cortex XDR now provides the ability to maintain the Broker VM applet configurations whenever an applet is deactivated. This ensures that whenever the applet is reactivated the saved configuration is restored.                                                                                                                        |
| Enhanced error visibility and auditing for additional Broker VM applets | Gain better insight into application, connectivity, and processing errors for the File and DB collector applets running on Broker VMs. Error messages are displayed on Apps of Broker VMs and Clusters, and applet status changes are logged in the collection\_auditing dataset, enabling detailed investigations through XQL queries. |

**XDR Collectors**

**XDR Collectors 1.5.0:** Windows 1.5.0.1733 and Linux 1.5.0.1695

**XDR Collectors 1.4.3:** Windows 1.4.3.1686

For more information on maintenance releases, see [Maintenance Releases](/cortex-xdr-3.x-rn/cortex-xdr-release-information/maintenance-releases.md)

| Feature                        | Description                                                   |
| ------------------------------ | ------------------------------------------------------------- |
| XDR Collectors 1.5.0 and 1.4.3 | This release includes performance improvements and bug fixes. |

**External Data Ingestion and Management**

| FEATURE                                         | DESCRIPTION                                        |
| ----------------------------------------------- | -------------------------------------------------- |
| VNET flow log support for Azure Network Watcher | Azure Network Watcher now supports VNET flow logs. |

**Cortex Query Language (XQL)**

| FEATURE                                                               | DESCRIPTION                                                                                                                                                                                           |
| --------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p>New XQL IP functions</p><p>(Requires a Cortex XDR Pro license)</p> | Cortex Query Language (XQL) now supports new functions for IP manipulations. These functions verify whether an input is a valid IPv4/IPv6 address and if the IPv4/IPv6 address is a known private IP. |

**Gateway**

| FEATURE                         | DESCRIPTION                                                                                                                                                                                          |
| ------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Improved user record management | Only users with at least one role or user group assigned are saved to Cortex Gateway, ensuring that the Gateway contains only relevant user data. This enhances data security and system efficiency. |

**Investigation and Response**

| FEATURE                    | DESCRIPTION                                                                                                                |
| -------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| Unified Identity Inventory | A unified inventory for identities features dedicated sections for investigating each domain: cloud, enterprise, and code. |

**Endpoint Security**

| FEATURE                   | DESCRIPTION                                                                                                                                                                                                                                                                                  |
| ------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Cloud-based host policies | Cortex XDR with agent 8.9 and later, enables cloud-based hosts to define policies based on important cloud attributes, such as cluster name, region, and provider. This gives the capability to define different security policies based on geography, responsibility, or specific clusters. |
| VBScript enhancement      | Cortex XDR with agent 8.9 and later, supports the ability to detect malicious VBScript files being written to disk.                                                                                                                                                                          |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-3.x-rn/cortex-xdr-release-information/features-introduced-in-2025-xdr/july-2025/feature-enhancements.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
